# Map data not displaying in 8.2.0

**URL:** <https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450>\
**Category:** Kibana\
**Tags:** maps\
**Created:** [June 16, 2022, 8:27pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450 "2022-06-16T20:27:05Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 16, 2022, 8:27pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/1 "2022-06-16T20:27:05Z")

</div>

Hi,  
Ive migrated from 7.16 to 8.2 but since then my maps are not displaying.  
The data is there and mapped with a gep\_point for the location. I also noticed the location is no longer displaying in the discover ie with the world symbol next to it. I guessing this is part of the problem. If I try to create a new map it detects the geo location field despite it not showing in the discover. It shows correctly in the data view/index pattern.  
Ive looked through the release notes but cant see what might have broken it.  
Any help would be appreciated. The data is ingested via logstash.

Thanks

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [June 16, 2022, 9:21pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/2 "2022-06-16T21:21:45Z")

</div>

Are you running in cloud or on-prem?  
What version are you running? You said 8.2 but is that 8.2.0 or 8.2.1, etc.  
When adding a "Documents" layer, does the data display when you change scaling to "limit results to 10000"?

---

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 17, 2022, 8:54am UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/3 "2022-06-17T08:54:49Z")

</div>

Hi Nathan,

Thanks for the reply. Using 8.2.0,  
No the data doesn't show when you limit to 10,000. Think that's default anyway.  
On Prem version

Would you expect the world symbol to show in the discover for geo data or has that changed in 8.2? Thats the only thing i can see is different from 7.16, mapped as geo\_point, maps doesn't complain ie saying no geo data found etc.  
No log errors. Put the same data back in to 7.16 and shows correctly. All other data in the environment shows correctly too, just the geo data not displaying.

Thanks

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [June 18, 2022, 5:30pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/4 "2022-06-18T17:30:37Z")

</div>

In console can you run the following command `GET /your_index_name/_mapping`, replacing 'your\_index\_name'. What are the results. What is geo field mapped as?

---

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 18, 2022, 9:04pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/5 "2022-06-18T21:04:21Z")

</div>

Hi Nathan,

Here what it returned, see below. it looks a bit messy as that's not what's in the template file i.e some additional fields like country\_iso\_code , is there some auto mapping occurring?:

partial extract:

```auto
"threatindicator" : {
          "properties" : {
            "city_name" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "continent_code" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "country_code2" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "country_code3" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "country_name" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "dma_code" : {
              "type" : "short"
            },
            "geo" : {
              "properties" : {
                "city_name" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "continent_code" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "country_iso_code" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "country_name" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "location" : {
                  "properties" : {
                    "lat" : {
                      "type" : "float"
                    },
                    "lon" : {
                      "type" : "float"
                    }
                  }
                },
                "postal_code" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "region_iso_code" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "region_name" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "timezone" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                }
              }
            },
            "ip" : {
              "type" : "ip"
            },
            "latitude" : {
              "type" : "half_float"
            },
            "location" : {
              "type" : "geo_point"
            },
            "longitude" : {
              "type" : "half_float"
            },
            "mmdb" : {
              "properties" : {
                "dma_code" : {
                  "type" : "long"
                }
              }
            },
            "postal_code" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "region_code" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "region_name" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "timezone" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            }
          }
        },

```

thanks

Martin

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 19, 2022, 1:26am UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/6 "2022-06-19T01:26:01Z")

</div>

@martb

perhaps take a look at this...

> [@Kibana Maps features not displaying (failed net::ERR\_CONTENT\_DECODING\_FAILED)](https://discuss.elastic.co/t/kibana-maps-features-not-displaying-failed-net-err-content-decoding-failed/302424/7):
>
> @quentin.renoux We think we have a work around / temp fix. Can you try setting this in elasticsearch.yml http.compression: true NOTE : There could be some security concerns with that setting Follow Here : [[Maps] Vector tiles from Elasticsearch are not loading in on-prem instances · Issue #130291 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/130291)

@Nathan_Reese is this something different?

---

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 19, 2022, 6:11pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/7 "2022-06-19T18:11:47Z")

</div>

There are similarities but before i investigate further did the fix not get pushed into 8.2 or have i misread?

I appreciate you getting back to me on this. Thank you.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 19, 2022, 7:19pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/8 "2022-06-19T19:19:48Z")

</div>

@martb  
Did you simply try to set the scaling not to vector tiles and see if that worked as shown as a workaround ? That's a 10 second check?

And would help confirm whether the fix is in or not?

I'll validate with a self-managed when I get home later today

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 19, 2022, 9:07pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/9 "2022-06-19T21:07:29Z")

</div>

That fix appears to be in 8.2.2, this would not have worked previously... I will do a quick 8.2.0 check as well.

Confirmed that fix is in 8.2.0, so that appears to not be the source of your issues.

Apologies for the side track

 ![Screen Shot 2022-06-19 at 2.05.36 PM](https://us1.discourse-cdn.com/elastic/original/3X/d/b/dbc436a3dedef3ecbe346c2d3fb7efe133a5d86b.jpeg)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 19, 2022, 9:16pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/10 "2022-06-19T21:16:10Z")

</div>

I do notice that there are 2 different `location` fields one is a `geo_point` the other is not... is that intentional?

> [@martb](#):
>
> ```auto
> "location" : {
> "type" : "geo_point"
> },
> 
> ```

> [@martb](#):
>
> ```auto
> "location" : {
> "properties" : {
> "lat" : {
> "type" : "float"
> },
> "lon" : {
> "type" : "float"
> }
> }
> },
> 
> ```

---

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 19, 2022, 9:19pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/11 "2022-06-19T21:19:02Z")

</div>

Hi,

I tried that but not difference.

The differences from my previous working version seems tobe the new geo fields that are now showing in the mapping template.  
Ive seen the same fields in the ECS. I did a test to change my mappings to match the new fields but this didnt make any difference.

The other thing that is jumping out at me is no geo field showing in the Discover ie the world symbol, it's detected in maps, but not showing in Discover.  
I've been using elastic for over 4 years and I know previously maps with logstash required you to define and set alot more in logstash and mapping. Is 8.x automatically setting the geo fields and therefore what's defined in my existing mapping is conflicting with the auto geo fields? Just a theory. Thanks Martin

---

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 19, 2022, 9:24pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/13 "2022-06-19T21:24:54Z")

</div>

Our messages crossed. The 2 locations fields are not intentional, also duplicate country fields etc. These seem tobe auto adding.. im now wondering if i simply delete my mapping template and see what is set by default. I suspect the duplicates will disappear.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 19, 2022, 9:37pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/14 "2022-06-19T21:37:13Z")

</div>

> [@martb](#):
>
> im now wondering if i simply delete my mapping template and see what is set by default. I suspect the duplicates will disappear.

We are starting to converge a bit.

I was going to suggest that... and if you do you should run `filebeat setup -e` again to load all the proper templates etc.

Did you upgrade filebeat to 8.2.0 as well?

Which module is this?

---

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 19, 2022, 10:11pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/15 "2022-06-19T22:11:42Z")

</div>

HI,

I'm quite sure filebeats would have been upgraded too, but I'll have to confirm that tomorrow too be 100%.

After ingesting the data without any predefined mappings the following was created. As expected there are no duplicates and all look a bit cleaner albeit IP not defined correctly(easy fix).  
As no geo\_point was set Maps nolonger sees a geospatial field. Location is now added with lat and lon. Previously I set location as: "location" : { "type" : "geo\_point" }. I'm now not sure what should be set as a geo\_point.

```auto
        "threatindicator" : {
          "properties" : {
            "geo" : {
              "properties" : {
                "city_name" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "continent_code" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "country_iso_code" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "country_name" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "location" : {
                  "properties" : {
                    "lat" : {
                      "type" : "float"
                    },
                    "lon" : {
                      "type" : "float"
                    }
                  }
                },
                "postal_code" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "region_iso_code" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "region_name" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                },
                "timezone" : {
                  "type" : "text",
                  "fields" : {
                    "keyword" : {
                      "type" : "keyword",
                      "ignore_above" : 256
                    }
                  }
                }
              }
            },
            "ip" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            },
            "mmdb" : {
              "properties" : {
                "dma_code" : {
                  "type" : "long"
                }
              }
            }
          }
        },

```

Many thanks

Martin

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 19, 2022, 10:57pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/16 "2022-06-19T22:57:25Z")

</div>

Just removing the template won't work for sure... You will need to run setup.

Because then you are just getting the default mapping.. which won't be correct.

What makes this even more difficult is if you remove the mapping / template and there's already filebeats out there writing. They will immediately write a document and you'll get the default mapping again and be right back is the same place.

You most likely need to run setup again get the right template and then ingest pipeline loaded.

Order I would do it...

- Stop all the beats
- Clean up bad indices / data streams
- Run setup
- Start the beats again

Also  
7.x beats write indices  
8.x beats write data streams

---

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 20, 2022, 9:23am UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/17 "2022-06-20T09:23:37Z")

</div>

Hi,

Just to clarify, I did understand that it wouldn't work when I removed the template, this was just to see why we had duplicate mappings. I doubled checked regarding Filebeat and it's not installed. I wasn't sure regarding the filebeat reference as we don't use it. Out data is coming in via Logstash connecting a MSSQL database.

Regards

Martin

---

<div class="post-metadata">

**Author:** ![martb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martb/32/78185_2.png) [@martb](https://discuss.elastic.co/u/martb)\
**Post date:** [June 20, 2022, 11:55am UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/18 "2022-06-20T11:55:52Z")

</div>

HI,

I found what the problem is. I'm not 100% sure when the change was introduced, possibly 7.17 but if you don't set ecs\_compatibility =\> disabled in your logstash file(filter) you will have conflicting mappings. Basically you end up with mixture of ECS geo mappings and your existing defined mappings.

To resolve this:

```auto
filter {
  geoip {
    source => "[host][ip]"
    ecs_compatibility => disabled
  }
}

```

Ref:  
https://www.elastic.co/guide/en/logstash/7.17/ecs-ls.html  
https://www.elastic.co/guide/en/logstash/current/plugins-filters-geoip.html

thanks for you help

Martin

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 20, 2022, 2:12pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/19 "2022-06-20T14:12:57Z")

</div>

Arg! `ecs_compatability` good find!, that has bit a few other folks too in other areas... should have thought of that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2022, 2:13pm UTC](https://discuss.elastic.co/t/map-data-not-displaying-in-8-2-0/307450/20 "2022-07-18T14:13:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
